2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10544uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate...
CVE-2016-10543call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 tha...
CVE-2016-10542ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date ...
CVE-2016-10541CRITICAL9.8The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shel...
CVE-2016-10540Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The ...
CVE-2016-10539negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Ko...
CVE-2016-10538The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allo...
CVE-2016-10537backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events ...
CVE-2016-10536engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-dire...
CVE-2016-10535csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail...
CVE-2016-10534electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with ...
CVE-2016-10533express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mon...
CVE-2016-10532console-io is a module that allows users to implement a web console in their application. A malicious user could bypass ...
CVE-2016-10531marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parse...
CVE-2016-10530The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can oft...
CVE-2016-10529Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to mak...
CVE-2016-10528restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Re...
CVE-2016-10527The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable unde...
CVE-2016-10526A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it di...
CVE-2016-10524HIGH8.2i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API e...
CVE-2016-10523MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS...
CVE-2016-10521HIGH7.5jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in t...
CVE-2016-10520HIGH7.5jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
CVE-2016-10519A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a...
CVE-2016-10518A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memo...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now